Skip to main content

Investigating an action

Find out who carried out an action in the Console, when it happened, which object was affected, and what the outcome was.

When to use this​

  • Use it when a rule, user, group, or account changed unexpectedly.
  • Use it when you need to evidence a change for an audit.
  • Use it when a team questions why an access changed.

Before you start​

  • Have an approximate time window.
  • Know which object was affected — a user, group, rule, or account.
  • Have a role that lets you view the audit trail.

Step by step​

  1. Open Audit Center.
  2. Filter by period.
  3. Add filters by person or object where you know them.
  4. Open the candidate records.
  5. Compare the time, the outcome, and the action's description.
  6. Export the evidence if you need to attach it to a process.

What happens next​

  • You will be able to explain the action based on the product's evidence.
  • If the action was improper, an administrator can correct the access.
  • The investigation may point to a need to review groups or rules.

Common errors​

  • Using the wrong period: the action may fall outside the results.
  • Confusing similar actions: read the details before concluding.
  • Overlooking earlier actions that set the change up.

Good practice​

  • Work with a timeline.
  • Keep the filters used in the investigation.
  • Review who is responsible for sensitive actions after incidents.

Next steps​